This will bring attention to it from our PM and allow the community to vote for the enhancement as well. I think this would be a simpler product approach to address this need.
Alternatively, there are Email Notification scripts in CmdCtrl that can be attached to CmdCtrl rules, but I'm not sure how we would configure it to notify when a user is auto blocked based on command risk..
There is also the Compliance Auditor, which might be useful in this regard.. This can be configured with an Audit Rule to "pull-in/sync" sessions that have "risky" commands based on the configured risk level. There is a life-cycle to manage these audit records so the organization can monitor/be aware of them. But you can also create an Audit Report from this perspective as well to notify certain users of new/pending audit records.
So to sum up the Compliance Auditor approach to this.. You could configure an Audit Rule to create Audit Records based on Command Risk filter that matches the command(s) you are interested in. Once they are in the Compliance Auditor, then they exist as Audit Records which point to the actual audited session keystroke report, etc. An Audit Report could be configured to automatically notify users of these new records on a particular schedule. These compliance-type users/admins could then come into the Compliance Auditor and view the Audit Record, make notes on the session and set the status to either Authorized or Unauthorized from an auditing perspective. This would be a good approach to ensure / verify the risky commands are handled appropriately. https://www.netiq.com/documentation/privileged-account-manager-35/npam_admin/data/bjglbku.html